Re: OpenSSH 3.9p1-portable PAM Authentication Remote Information Disclosure

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, Dec 07, 2004 at 05:21:30PM -0500, Marcus Lauer wrote:
>         I do hope that somebody fixes this, though.  Any bug which
> allows a dictionary attack on the root account, unlikely as it is to
> work, is still surely a bad thing.

If you're worried about that, and this _is_ the earlier issue, I believe
there's a simple workaround: use the 'nodelay' flag to pam_unix.



-- 
Matthew Miller           mattdm@xxxxxxxxxx        <http://www.mattdm.org/>
Boston University Linux      ------>                <http://linux.bu.edu/>

--

fedora-legacy-list@xxxxxxxxxx
http://www.redhat.com/mailman/listinfo/fedora-legacy-list

[Index of Archives]     [Fedora Development]     [Fedora Announce]     [Fedora Legacy Announce]     [Fedora Config]     [PAM]     [Fedora General Discussion]     [Big List of Linux Books]     [Gimp]     [Yosemite Questions]

  Powered by Linux